Cosign v0.3.0 Release Notes

  • ๐Ÿš€ This is the third release of cosign!

    We still expect many flags, commands, and formats to change going forward, but we're getting closer. ๐Ÿš€ No backwards compatiblity is promised or implied yet, though we are hoping to formalize this policy in the next release. ๐Ÿ‘€ See #254 for more info.

    โœจ Enhancements

    • ๐Ÿ‘ The -output-file flag supports writing output to a specific file
    • ๐Ÿšš The -key flag now supports kms references and URLs, the kms specific flag has been removed
    • ๐Ÿ‘ Yubikey/PIV hardware support is now included!
    • ๐Ÿ‘Œ Support for signing and verifying multiple images in one invocation

    ๐Ÿ› Bug Fixes

    • ๐Ÿ› Bug fixes in KMS keypair generation
    • ๐Ÿ› Bug fixes in key type parsing

    Contributors

    • Dan Lorenc
    • Priya Wadhwa
    • Ivan Font
    • Depandabot!
    • Mark Bestavros
    • Jake Sanders
    • Carlos Tadeu Panato Junior